CiberLATAMbywhalemate
Intelligence report

Colombia Cybersecurity Situation, August 2026

Ransomware dominated August in Colombia: 122 verified incidents, 66 linked to extortion, 12 fraud cases, and 6 regulatory changes.

Sep 1, 202618 min read
Colombia Cybersecurity Situation, August 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified facts dated within the period. Each one states its source base and counting criterion so the figures reconcile across modules. They are the recurring month-to-month readout; the analysis that follows develops the cases without repeating this summary.

Indicator window: 122 dated facts in August 2026 · 1 from prior months (comparative frame, not month volume) · 2 without confirmed date (excluded from the indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard August 2026 · Colombia Primary threat: Ransomware (66 of 122 events). Coverage: 122 dated events in August 2026 · 1 of prior months… VERIFIED EVENTS 122 period base: all counts measured from below based on this total RANSOMWARE / EXTORTION 66 5 encrypted assets confirmed · 2 exfiltration unencrypted (simple extortion) UNCLASSIFIED INCIDENTS 22 breaches or outages without declared threat type FRAUD / PHISHING 12 documented fraud campaigns documented REGULATION 6 rules, resolutions, or sanctions UNIQUE CVEs 1 CVE-2026-50522
Monthly verified signal dashboard — Base: 122 verified events dated within the period for Colombia.
MONTHLY FIXED MODULE Threat Axis Distribution August 2026 · Colombia Each event counts in only one axis, so the total is exactly 122. "Unclassified incidents" is the remainder. Ransomware 66 Incidents 22 Unclassified 14 Fraud 12 Regulation 6 Vulnerabilities 2
Threat Axis Distribution — Each event is assigned to one axis based on its classification; the total reconciles with the 122 events in the period.
FIXED MONTHLY MODULE Sectoral distribution of signals August 2026 · Colombia Base: 122 events in the period · total 169 because 44 events are classified in more than one sector. Public sector / OIV 89 Telecom 30 Others / unspecified sector… 18 Finance 14 Energy 8 Technology 6 Retail / Consumer 2 Education 2
Sectoral distribution of signals — Heuristic sector classification by victim. One event may affect more than one sector, so totals may exceed the base.
MONTHLY FIXED MODULE Critical infrastructure in Colombia August 2026 · Colombia 72 of 122 incidents in the period involve critical infrastructure. One incident may appear in more than one category. Public sector / government 89 Telecom / connectivity 23
Critical infrastructure in Colombia — Verified incidents involving the public sector, utilities, and essential services

Executive monthly summary for Colombia

The month’s most concrete event in Colombia was the ransomware attack on the Ministry of Justice, confirmed since August 2 and still in recovery at the end of August, with degraded operational continuity and alternate channels still active. That case set the tone for the period: 122 verified incidents, 66 tied to ransomware or extortion, 12 fraud or phishing cases, 22 unclassified incidents, and 6 regulatory moves.

The dominant signal was clearly offensive. Ransomware accounted for the largest share, and within that set the available material confirmed 5 cases with asset encryption, 2 with exfiltration without encryption, 2 mentioned only on leak sites, and 57 where the exact classification could not be determined. The available source also shows that much of the activity was driven by recurring campaigns and reports, not just a single isolated episode.

At the same time, digital fraud gained ground. There were 12 documented cases, including bank impersonation campaigns, fake SMS messages, deceptive calls, and scams backed by synthetic identities or biometrics. The pressure was visible in the financial system, in immediate payment services, and in migration or operational change processes, where attackers took advantage of user confusion.

The regulatory picture was active, although with lower volume than in July. Six policy moves were documented, down from 18 the previous month, with a focus on disaster relief, responses to identity theft, open finance, data protection, and rules on AI. The combination of a real incident, mass fraud, and regulatory adjustment raises the country risk level to high for August, especially because of the operational severity of the ransomware and the persistence of deception campaigns.

National Snapshot for the Month in Colombia

Colombia ended August with high, visible exposure, shaped by a central ransomware case in the public sector, multiple fraud alerts, and an active but narrower regulatory front than in July. The month’s severity was concentrated in the partial unavailability of services at the Ministry of Justice, especially the SGDEA and related procedures, and in repeated alerts tied to banking and digital impersonation.

The leading threat was ransomware, with 66 of 122 verified incidents during the period. That does not mean the full volume reflected a single intrusion, because the material combines incidents, technical writeups, and follow-up references. It does show sustained pressure on public entities, digital service operators, and organizations with exposed cloud, remote, or perimeter surfaces.

Fraud signals were also consistent. The month’s reports described bank impersonation, fake virtual assistants, text messages about pending payments, calls made in the name of public entities, and deceptive donation campaigns after the earthquake. The pattern was not new, but it was more visible and closer to urgent or operational transition contexts, which increases the effectiveness of the deception.

In sectoral terms, the material touched seven sectors with at least one documented incident. The public sector accounted for the most serious case, while banking, telecommunications, digital services, regulation, critical infrastructure, and health or digital consumer services contributed secondary signals. The mix fits a country where the digital attack surface is broad and where an incident at a single entity can affect continuity, service delivery, and document traceability.

Colombia, agosto 2026, hitos de ciberseguridadLínea temporal de los principales hitos verificados del mes en Colombia.August 2026Aug 2COLCERT highransomwareAug 3 MinJusticeconfirms attackAug 4SharePointcritical alertAug 15 recoveryinteragencyAug 20PQRDSFin contingencyAug 31 plancomprehensiverecoveryMilestonesbuilt onlywith factsdated August2026.
Colombia, August 2026, cybersecurity milestones — Verified milestones of the month in Colombia, focusing on ransomware, fraud, regulation, and critical vulnerabilities.

Regionally, Colombia remained one of the most visible countries in Latin America for ransomware incidents and for the combination of accelerated regulation, banking fraud, and service disruption. The month also left an important signal in digital infrastructure, with references to critical vulnerabilities in hosting platforms and network outages that, although not always attributable to cyberattack, reinforce the operating fragility of the environment.

Colombia period indicators

Indicator August 2026 Previous month Change
Verified events in the period (base for all indicators) 122 76 +46
Indicator time window 122 events dated August 2026, 1 from previous months, 2 without confirmed dates excluded from the indicators 76 events from the previous month N/A
Unclassified incidents (breaches or outages) 22 18 +4
Cases with ransomware or extortion as the primary focus 66 30 +36
Confirmed asset encryption 5 not reported N/A
Exfiltration without encryption (simple extortion) 2 not reported N/A
Leak site mention only 2 not reported N/A
Classification not determinable from the material 57 not reported N/A
Documented fraud or phishing cases 12 1 +11
Documented regulatory moves 6 18 -12
Critical CVEs mentioned 1 1 no change
Sectors with at least one documented event 7 7 no change
Dominant threat of the month Ransomware (66 of 122 events) Ransomware (30 of 76 events) N/A
Events with direct source confirmation 80% not reported N/A

Relevant incidents in Colombia

Ministry of Justice and Law, ransomware with operational impact

The month’s most significant case was the ransomware attack against the Ministry of Justice and Law, which occurred on August 2 and was publicly confirmed the next day. It partially affected technology infrastructure and digital services. The incident remained active throughout the month, with gradual recovery, continuity through alternate channels, and forensic tracing still underway.

The Ministry said COLCERT inspected the datacenter, secured evidence and logs, and supported remediation efforts. It also said it had received no prior alerts and that some systems, including the SGDEA, were temporarily unavailable. Specialized coverage added that services tied to monitoring illicit drugs and judicial processes were compromised.

The available material confirms file encryption and operational degradation, but it does not provide conclusive public evidence of exfiltration. That distinction matters. The incident was not limited to a leak-site claim, but caused real service disruption, with recovery still in progress at month-end.

Ministry of Justice, continuity, recovery, and interagency response

Throughout August, the Ministry kept communicating publicly and rolled out contingency measures. It enabled in-person support, an alternate email address, and a phone line, and later asked that PQRDSF submissions filed through the Virtual Single Window be resent so it could rebuild records affected by the SGDEA outage.

The response expanded through a working group that included the Attorney General’s Office, COLCERT, Microsoft’s DART team, and BID partners. By the end of the month, the Ministry announced a comprehensive technology recovery plan to strengthen its infrastructure and ensure the delivery of essential services.

The sequence points to staggered recovery, but also to a basic weakness in records and citizen-service processes. The impact was not limited to immediate unavailability. It also disrupted traceability, request management, and response times.

CRC, risk to fixed internet users amid dispute between TV Azteca and ATP

On August 22, the Communications Regulatory Commission warned of a potential interruption affecting about 57,000 fixed internet users served by 245 small ISPs in 261 municipalities, because of a contractual dispute between TV Azteca and ATP. The agency clarified that there was no confirmation of an actual cutoff at the time of the notice.

This was not a cybersecurity incident in the strict sense, but it did signal continuity fragility in connectivity infrastructure. For Colombia, the key point is that reliance on smaller providers can amplify the effects of contractual disputes or technical failures for end users.

Movistar, widespread outage of internet, TV, and mobile phone service

On August 13, Movistar users reported widespread outages in fixed and mobile services in several cities across the country. The company said the cause was damage to its fiber-optic network in multiple locations, along with earlier earthquake-related impacts.

The case did not qualify as a cyberincident because the material does not attribute it to an attack. Even so, it was one of the disruptions absorbed by Colombia’s digital market in August, and it helps explain why continuity and resilience were central to the operational agenda.

Alert over critical vulnerability in Microsoft SharePoint Server

COLCERT issued alert AL-20260804-108 about a critical vulnerability in Microsoft SharePoint Server, while international technical coverage identified the flaw as CVE-2026-50522 and reported active exploitation on Internet-facing servers. The material available for Colombia does not include affected versions or full remediation guidance.

The relevance for the country is twofold. First, SharePoint is part of the usual perimeter for public agencies and companies with on-premises deployments. Second, the emergence of an actively exploited critical vulnerability coincided with the period of high operational strain at the Ministry of Justice.

Threats and active campaigns in Colombia

Ransomware in Colombia: confirmed encryption, partial exfiltration, and multiple uncategorized mentions

August was dominated by ransomware, but the material does not support treating the entire signal as a single type of impact. There were 5 cases with confirmed asset encryption, 2 with exfiltration without encryption, 2 that appeared only on a leak site, and 57 where the type could not be established with precision.

The Ministry of Justice falls into the first group. There, files were encrypted, services were degraded, and containment measures were taken, although there was no public proof of data theft. At the same time, the PIO PIO case attributed to Majinahanashi appears as an exfiltration with a threat to leak data, and the AuditTeam entry on a financial institution remains at the level of a leak site mention.

The operational takeaway is more useful than the broad label. In Colombia, August ransomware combined real operational disruption with several levels of extortion pressure, and the available material does not justify counting all of it as the same thing. Attribution also remained open in several cases.

Fraud and phishing in Colombia: bank impersonation, fake messages, and deceptive calls

Digital fraud became denser and more visible, with 12 documented incidents in August. The tactics included messages about a "pending payment" or "pending transfer," fake banking security assistants, emails with court summons or fines, calls from supposed bank officials, and fake donation campaigns after the earthquake.

The clearest cases were concentrated in banking and payments. Bogotá issued alerts about impersonation of Bre-B, the mayor's office warned about fake virtual assistants, and El Colombiano documented banking scams involving supposed security accounts and loans arranged with upfront payments. There were also alerts about fake subsidies from the Registraduría and fraudulent donations.

The month points to a simple pattern. Attackers exploited moments of urgency, customer migrations, process changes, and confusing service channels. That means fraud depends not only on volume, but also on timing and context.

Campaigns and technical exploitation in Colombia: the APT or persistent intrusion signal remained limited

Beyond ransomware and fraud, the month also left a technical signal in vulnerabilities and intrusion campaigns, although without a robust body of facts that would support speaking of a Colombia-focused APT. The SharePoint alert and reports on cPanel/WHM showed a significant risk surface for hosting, SaaS, and shared infrastructure.

The StrikeShark campaign also surfaced, identified by Kaspersky and cited in regional material, which included Colombia among the affected countries. However, the available material does not provide a verified local victim in this period or enough detail to classify it as a fully characterized Colombian campaign.

Critical vulnerabilities affecting Colombia

CVE Software Exploitation Source
CVE-2026-50522 Microsoft SharePoint Server Active exploitation reported on Internet-exposed on-premises servers Mallory.ai
CVE-2026-65643 cPanel and WHM Privilege escalation confirmed, with critical risk for hosting and data centers Threadlinqs Intelligence, CSIRT Telconet
CVE-2026-70355 Microsoft SharePoint Server Vulnerability patched in August Patch Tuesday, mentioned in regional bulletins CSIRT Telconet
CVE-2026-68820 Windows afd.sys Active exploitation in espionage campaigns, with potential impact on Windows endpoints Microsoft, Greenbone, SC World

The table brings together the critical identifiers mentioned in this month’s material, but only one is directly tied to a formal Colombian alert, the SharePoint one. The others provide regional exposure context and patch-hardening guidance, not confirmed local incidents.

Regulation and compliance in Colombia

Colombia ended August with an active regulatory front, although more concentrated than in July. There were six documented moves, down from eighteen the month before, with priority given to relief for financial consumers, digital identity, AI, personal data, and the organization of open finance.

Regulatory focus Documented action Practical scope
Financial consumer protection External Circular 007 of 2026 and External Circular Letter 54 of 2026 from the Financial Superintendency Post-disaster relief, fast-track complaints, channel transparency, and refinancing deadlines
Digital identity Statutory Law 2573 of 2026 Staged obligations for financial, commercial, and telecommunications entities
Data protection SIC Circular 001 of 2025 and the August 25 deadline for the RNBD Stronger rules on consent, biometrics, and reporting of updates
AI Bill 025 of 2026 and related legislative debates Risk assessments, human oversight, and governance of AI systems
Open finance Decree 368 of 2026 and a draft external circular dated August 31 Milestone for mandatory common standards and a technical timeline

The Financial Superintendency was the most visible agency of the month. It stepped up support for consumers affected by the disaster, published External Circular 007 with deadline limits for refinancing, and kept the "Quejas exprés" complaint system in place. That is not pure cybersecurity, but it is part of the broader digital financial resilience environment.

On personal data, the SIC kept its focus on the RNBD and on the processing of biometrics. The closure order against World Foundation and Tools for Humanity, together with alerts about iris data and impersonation, showed that the regulatory debate is no longer centered only on consent. It is now also about the effective deletion of sensitive data and technical proof of compliance.

In AI, the month left a regulatory framework still under construction, with bill proposals, criticism over how workable the rules may be, and debate over algorithmic surveillance, biometrics, and automated decisions. The field is not settled, but it is becoming a compliance vector that is starting to intersect with fraud, identity, and model audits.

Colombia, agosto 2026, cambio regulatorio frente a julioGráfico de barras comparando movimientos regulatorios documentados en julio y agosto de 2026.Regulatory movementsJuly 2026August 2026186Comparison based on verified data from the previous report
Colombia, August 2026, regulatory change versus July — Simple comparison of verified regulatory volume between July and August 2026.

Most Affected Sectors in Colombia

The public sector was the main target in August, with the Ministry of Justice as the central incident and additional signs of impact on public safety, service continuity, and records management. The disruption was not only technical, but administrative as well, with requests being rerouted, alternate channels activated, and case histories rebuilt.

Banking and financial services were the second major focus, not because of a large intrusion incident, but because of the volume of fraud. Alerts about bank impersonation, Bre-B, fake assistants, and customer migrations point to a heavily exploited risk surface, where social engineering remains more profitable than complex technical exploitation.

Telecommunications and digital infrastructure produced two kinds of signal. One was about continuity, with Movistar’s widespread outage and the CRC warning about possible disruptions for smaller ISPs. The other was technical, with the BGP alert and the critical vulnerability in cPanel/WHM, which affect the core of connectivity and hosting.

Regulatory and data protection activity also appeared, especially in supervised entities, fintech, and biometric processing. The mix of sectors is not accidental, the month showed that risk in Colombia crosses documents, identity, payments, connectivity, and government services with far less separation than is often assumed.

The clearest shift from the previous month was the jump in ransomware and fraud. Ransomware rose from 30 cases in July to 66 in August, while fraud and phishing increased from 1 to 12. Regulatory activity, by contrast, fell from 18 to 6, suggesting the month was driven more by incidents and campaigns than by new rules.

Indicator July 2026 August 2026 Reading
Verified events 76 122 Information and operational pressure increased
Unclassified incidents 18 22 The noise from inconclusive events rose
Ransomware or extortion 30 66 It became the dominant focus and intensified
Fraud or phishing 1 12 Deception and impersonation signals surged
Regulatory moves 18 6 There was less rulemaking activity than in July
Critical CVEs 1 1 No change in volume, but active risk remained
Sectors with events 7 7 Sector coverage held steady

The comparison also shows that the country did not change its risk map, only its intensity. The same sectors remained in play, but the public sector was hit harder and the financial system faced more fraud attempts. At the same time, the mention of just one critical CVE does not reduce the technical risk, because August did show active exploitation in widely deployed infrastructure.

Another signal to watch is the coexistence of recovery and exposure. MinJusticia kept restoring services, but alerts around identity, biometric data, open finance, and platform exploitation continued. That makes resilience a process issue, not just a perimeter issue.

August also left a warning about third-party dependence. The Ministry of Justice case involved Microsoft’s DART team and the IDB in recovery efforts, while telecom and hosting cases raised risks tied to smaller vendors, shared infrastructure, and exposed control panels. That is the kind of attack surface that grows fastest when digitalization outpaces operational maturity.

Security recommendations for teams in Colombia

First, review exposure from remote services and the hygiene of privileged accounts. This month showed that ransomware still gets in through credentials, exposed access, and remote administration platforms. Phishing-resistant MFA, closing unnecessary RDP, and real segmentation are not optional.

Second, strengthen controls over email, SMS, calls, and messaging. Fraud campaigns exploited bank impersonation, pending payment messages, fake assistants, and court summons. It makes sense to tighten filters, detect lookalike domains, enable out-of-band validation, and train users with local examples, not generic ones.

Third, protect sensitive and biometric data with a focus on traceability. The iris case in Cartagena, the debate about the SIC, and digital identity obligations point to a problem that does not end with collecting data. Organizations must be able to prove why it was collected, who accessed it, when it was deleted, and how they respond to a complaint.

Fourth, prepare continuity plans specific to document systems and citizen services. MinJusticia showed that a down SGDEA can force teams to rebuild case files, reopen manual workflows, and keep service running through alternate channels. Business continuity plans should account for that kind of degradation, not just a total site outage.

Fifth, prioritize patching hosting panels, SharePoint, and edge components. Alerts on CVE-2026-50522 and CVE-2026-65643 confirm that a well-placed vulnerability can become a critical entry point. If a public service or a third-party provider depends on those products, the exposure window should be treated as urgent.

Frequently Asked Questions

What explains why August saw more ransomware and less regulation in Colombia?

August was dominated by a major ransomware case at the Ministry of Justice and several related campaigns and reports, while regulatory output fell compared with July. The comparison between the two sections shows more operational pressure and less regulatory activity, although digital identity, data, and open finance remained on the agenda.

What is the difference between confirmed ransomware cases and mentions on a leak site?

In August there were 5 cases with confirmed encryption, 2 with exfiltration without encryption, and 2 mentioned only on a leak site. That distinction matters because a leak site by itself does not prove operational impact or verifiable exfiltration. The threat and incident sections separate those levels so extortion is not confused with real disruption.

How are the Ministry of Justice case and the SharePoint alert in Colombia connected?

They are connected by technical surface and timing. The Ministry of Justice suffered ransomware with degraded services, while COLCERT issued an alert about SharePoint Server and international reporting pointed to active exploitation of a critical flaw. The vulnerabilities table and the incidents table show that both issues occurred in the same month.

Which sectors should security teams in Colombia watch most closely?

The public sector, because of the direct impact of ransomware at MinJusticia, and the financial sector, because of the rise in banking fraud and Bre-B impersonation. Telecommunications, hosting, and digital services also need attention, because the month raised signals about continuity, BGP, control panels, and exposed providers.

What concrete controls became more urgent after August?

Phishing-resistant MFA, shutting down unnecessary remote access, rapid patching for SharePoint and cPanel/WHM, monitoring for banking impersonation in SMS and calls, and continuity plans for SGDEA and other document systems. Those priorities come from the incidents, threats, vulnerabilities, and recommendations sections.

Does the indicator of a single critical CVE mean there were no other serious vulnerabilities in the region?

No. It means that in the material analyzed for Colombia during August, only one critical CVE was recorded within the scope of the report. The limitations section makes clear that a low or zero value in an indicator does not mean there was no regional risk, only that no verified records were found in this corpus.

Material limitations

The report was built exclusively from the facts provided for Colombia in August 2026, plus one fact from earlier months used only as a comparison point. The time window for the indicators was the one stated at the start, with 122 facts dated in August, 1 from earlier months used only for comparison, and 2 without a confirmed date excluded from the counts.

An indicator at 0 or without a breakdown, especially for CVEs, does not mean there were no vulnerabilities or exploitation in the region. It means that data point was not recorded in the material analyzed for this period. The same applies to categories where the material did not allow confirmation of whether there was encryption, exfiltration, or only a mention on a leak site.

The analysis did not include aggregated telemetry such as the volume of blocked attempts, because the material did not provide figures of that kind. Nor were trends based solely on sponsored content, commercial releases, or consumer publications without primary corroboration used as support.

Facts without a confirmed date and any material not included in the list of available sources to cite were left out of the indicators. References to social media, when they appeared in the file, were used only if the fact was also supported by a permitted and verifiable source within the corpus.

Sources